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Abstract 

We study the quantum query complexity of finding a certificate for a d-regular, fc-level 
balanced NAND formula. We show that the query complexity is Q(S k+1 ^ 2 ) for O-certificates, 
and Q{d k ' 2 ) for 1 -certificates. In particular, this shows that the zero-error quantum query 
complexity of evaluating such formulas is 0(S k+1 ^ 2 ). Our lower bound relies on the fact that 
the quantum adversary method obeys a direct sum theorem. 

1 Introduction 

Recently, there has been considerable progress in understanding the quantum query complexity of 
evaluating Boolean formulas. Here, we consider the closely related problem of certifying the value 
of a formula. 

An n-bit Boolean formula <j) corresponds to a rooted tree with n leaves, where each leaf represents 
a binary variable Xi for i G {1, . . . ,n}, and each internal vertex represents a logic gate acting on 
its children. We can evaluate <j> on an input x G {0, l} n by applying the logic gates from the leaves 
toward the root, giving some binary value <f>(x) at the root. Suppose we are given a black box that, 
on input i, produces the bit X{. The minimum number of queries to such a black box required to 
learn 4>{x) for an arbitrary x G {0, l} n is called the query complexity of evaluating <p. 

In this article, we focus on the case of NAND formulas, in which each internal vertex corresponds 
to a nand gate. (Note that formulas consisting of AND, OR, and NOT gates are equivalent to NAND 
formulas.) Furthermore, we suppose that the tree is regular, with internal vertices of degree d, and 
balanced, with a total of k levels. Thus, there are n = d k input variables. 

To evaluate such a formula on a black-box input, a deterministic classical computer must make 
all n queries. However, the expected number of queries for a randomized classical computer to 
evaluate the formula with zero error is O(A^) (T5][TT]. where A^ := (d— 1 + V d 2 + 14d + l)/4, using 
a simple recursive strategy. Indeed, this is the optimal query complexity not just for zero-error 
algorithms [15] . but also for bounded-error ones [16J. If we fix d and let k grow, this represents a 
polynomial speedup over the deterministic strategy of evaluating all leaves, since only 0(n lo Sd A d) 
queries are required; for example, with d = 2, the classical query complexity is 0(n ' 753 — ). On the 
other hand, if we fix k and let d grow, then the query complexity is essentially n. 

For quantum computers, the situation is quite different. Grover's algorithm shows that if k = 1, 
so that d = n, a quantum computer can evaluate the formula with bounded error in 0(y/n) queries 
[llj . which is optimal [6]. Similar results can be obtained for constant k: a recursive strategy with 
straightforward error reduction uses queries [7], and a more delicate approach to 
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error reduction uses 0(^/nc k ) queries for some constant c [13]. In particular, this shows that the 
quantum query complexity is 0(y/n) provided k is constant. However, for k growing with n (say, 
with constant d), no better quantum algorithm than the classical one was known for nearly ten 
years. A breakthrough occurred with the revolutionary quantum walk approach of |10j . which — 
combined with a simple observation on the simulation of Hamiltonian dynamics by quantum circuits 
[9] — showed that queries suffice for the case where d = 2. Subsequent work showed that in 

fact the quantum query complexity is 0(y/n) for any d, k [3]. Since this is optimal [2J, the quantum 
query complexity of evaluating balanced nand formulas is now a closed problem. 

Here, we consider the problem of determining a minimal certificate for the value of a NAND 
formula. A certificate for (j) on input x £ {0, l} n is a subset c C {1, . . . , n} such that the values of 
Xi for i £ c determine (j>(x). We say that a certificate c is minimal if no proper subset of c is also a 
certificate. 

We can view the size of the minimal certificate as a kind of nondeterministic query complexity, 
since this is the number of queries required to verify the value of the formula if we can guess the 
certificate. The certificate size of a regular, balanced nand formula can be understood simply, as 
follows. Let Cb(k) denote the size of a minimal certificate for a fc-level balanced nand formula 
evaluating to b (a b- certificate). We have Co(0) = Ci(0) = 1, and 

C (k)=dCx(k-l) Ci(A0 = Cb(A:-l). (*) 

Solving this recursion, we obtain 

Co(k) = { dk /* kGVen C 1 (k) = { dk ( [\ y2 keVen (2) 

v ; |y fc+1 )/ 2 k odd [d^-V/ 2 k odd. 

Thus, the certificate size is precisely y/n for a formula with an even number of levels, and is close 
to that value when the number of levels is large and odd. Note that a minimal 0-certificate is a set 
of inputs for k even and a set of 1 inputs for k odd; a minimal 1-certificate is a set of 1 inputs 
for k even and a set of inputs for k odd. 

Given a regular, balanced nand formula and a black box for the input, we are interested in 
the number of queries required to output a minimal certificate. This question is of interest for 
several reasons. Whereas the optimal classical algorithm for evaluating a nand formula produces 
a certificate in the course of its evaluation, the same does not hold for the known optimal quantum 
algorithms, so it is natural to ask whether quantum computers have a comparable advantage for 
certification as they do for evaluation. (The algorithm of [3] produces a quantum state that is 
related to certificates, which suggests a potential approach to certificate finding, but it turns out 
that a simpler strategy is nearly optimal.) In addition, the query complexity of certificate finding 
gives an upper bound on the zero-error query complexity of the problem (as emphasized in [8]), 
although it is not known if this bound is optimal in general. 

For a constant number of levels k, the previous best quantum algorithm for certifying a NAND 
formula uses queries in the case of O-certificates, and 0(d^ k+1 ^ 2 ) in the case of 1- 

certificates Lemma 1]. We improve upon this, and also give a result for non-constant k, as 
follows: 

Theorem 1. Consider a d-regular, k-level balanced NAND formula (ft with black-box input x. The 
bounded-error and zero-error quantum query complexities of certifying ((f), x) are 

0{k 2 d {k+l)/2 ) and n(d {k+1)/2 ) if<p(x) = (3) 
0{k 2 d k/2 ) and n(d k/2 ) if<j)(x) = l. (4) 

In particular, the zero-error quantum query complexity of evaluating 4>(x) is 0{k 2 S k+l )i 2 ). 
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The upper bound comes from a strategy that applies the formula evaluation algorithm of [3] 
recursively, as described in Section [2 The lower bound appeals to direct sum theorems. We discuss 
a direct sum theorem for adversary lower bounds in general in Section [3j and apply it to certification 
in Section HI We conclude in Section [5] by mentioning a few open questions. 

2 Algorithm 

To find a certificate for a nand formula, consider the following simple recursive strategy. First 
evaluate the root using the 0(y / n)-query algorithm of [3]. If the result is 0, each child of the root 
must evaluate to 1, and we can find a 1-certificate for each in turn. If the result is 1, then we search 
for a child evaluating to using Grover's algorithm combined with formula evaluation, and then 
find a 0-certificate for it. 

This strategy gives a nearly optimal algorithm for certificate finding. However, we must be 
careful when applying the formula evaluation algorithm recursively, since it only succeeds with 
bounded error, and we must ensure that this error can be kept under control. 

To find a 6-certificate for a k-level tree, we can apply the procedure A^k), defined as follows. 

Procedure Ao(k). 

• If k = 1, query every leaf. If they are all 1, then output every index; otherwise, go into an 
infinite loop. 

• If k > 1, run Ai(k — 1) on each subtree. 
Procedure Ai(fc). 

• If k = 1, repeat Grover's algorithm until a 0-leaf is found, verifying the result to ensure 
one-sided error. When a 0-leaf is found, output its index. 

• If k > 1, repeat the following until passing the verification: 

— Perform robust quantum search [13] for a 0-subtree, using the NAND tree evaluation 
algorithm [3j as a subroutine. (Note that robust quantum search has two-sided error.) 
Repeat the search until a 0-subtree T is found. 

— Verify that T is a 0-subtree with error probability at most 1/n 2 by running the NAND 
tree evaluation algorithm O(logn) times and taking a majority vote. 

• Once T passes the verification, run Ao(k — 1) on T. 

A simple inductive argument shows that Ab{k) will never terminate when given a formula 
evaluating to b. Furthermore, when Ab(k) does halt, it is guaranteed to return a correct 6-certificate. 
It remains to understand how long it takes for Aj)(k) to produce an 6-certificate. 

Lemma 2. Suppose that Ab(k) is given a d-regular, k-level balanced NAND formula evaluating to b. 
Assume that the verification step in procedure A\ never makes an error. Then the expected number 
of queries before Ao{k), A\{k) terminates is 



Proof. Let E[^4b(/c)] denote the expected number of queries made by A^{k) when given a formula 
evaluating to b, assuming the procedure A\ never makes an erroneous verification. For k = 1, we 




(5) 



respectively. 
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have EL4 (1)] = d and EL4i(l)] = 0(Vd). For k>2, 

E[A!(k)] = O(d k / 2 ) + O(d ik - 1)/2 logn)+E[A (k-l)] (6) 
= o((l + £^)d fc / 2 ) +E[Ao(k-l)] (7) 



and 



Solving this recurrence gives 



and 



E[A (k)} = dEiA^k - 1)}. (8) 



E[Ax(k)} = o(k(l + fc^) V#) (9) 



E[A {k)]=o(k(l + k 1 ^)VdF+^') (10) 

as claimed. □ 

Of course, we cannot actually assume that A\ never makes a verification error, but we can 
nevertheless obtain a zero-error algorithm for ^-certification as follows. Fix some sufficiently large 
constant c. Run A^ on the input; if it does not halt after ck(l + klogd/\/ r d)d^ k+1 ^ 2 queries (for 
b = 0) or ck{l + klogd/Vd)d k / 2 queries (for b = 1), then restart. The probability that one or more 
verifications fail during each trial is O ( (log 2 n)/n), since the error probability of each verification 
is at most 1/n 2 , and the total number of verifications per trial is at most the total number of 
queries, which is upper bounded by 0(n log 2 n). If a failure occurs during a given trial, then the 
algorithm will either output a correct certificate or will not terminate during that trial. Thus we 
only expect 0(1) repetitions to be required before the process terminates with a correct certificate, 
and we obtain an unconditional zero-error quantum algorithm with an expected running time given 
by Lemma El 



3 A direct sum theorem for the adversary method 

We now turn to the question of lower bounds. Our approach to the lower bound for certificate 
finding is based on the concept of a direct sum theorem. A direct sum theorem says that if solving 
one instance of a problem requires q queries, then solving t instances requires Q(tq) queries. (Sev- 
eral papers on quantum lower bounds — e.g., [2J[l4] — have studied direct product theorems, which 
are stronger statements. In particular, a strong direct product theorem says that if an algorithm 
attempts to solve t instances with o(tq) queries, then it can only succeed with an exponentially 
small probability. In this paper, we only need direct sum theorems.) 

One of the main methods for proving lower bounds on quantum query complexity is the quantum 
adversary method PQ, which can be reformulated as follows [5]: 

Theorem 3. Let S C {0, l} n , and let E be a finite set. For any function f : S — > E, define 

ADV(/): = maX m< J" oA|| , (U > 

where \\-\\ denotes the spectral norm; T ^ is a symmetric, entrywise non-negative \S\ x \S\ matrix 
satisfying T xy = if fix) = f{y); {Di) xy = 1 if Xi / yi and {Di) xy = otherwise; and o denotes 
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the Hadamard (i.e., entrywise) product of matrices. Finally, let Q e (f) denote the minimum number 
of quantum queries to x needed to compute f(x) with error at most e. Then 



Qe(J) > 1 2v/ 2 £(1 £) ADV(/). (12) 

We show that the quantity ADV(/) obeys a direct sum theorem, as follows. 

Theorem 4. Let S C {0, l} n , and let £ be a finite set. Given a function /W : S — ► E, let 
fit) . gt _^ s t be the function defined by f®(x) := (f^(xi . . . x n ), . . . , (^(t-l)n+l • • • x tn))- 
Then ADV(/W) = t ADV(/W). 

Proof. Let I?W be an optimal adversary matrix for /W, and let := <g> I ' -1 + J tg> r(* _1 ), 
where I denotes the |5"| x |5| identity matrix. Choosing T = r^, the numerator of ADV is 

l|r(*)|| = t||r«||. 

Now let Df ] denote the \Sf x |Sf matrix with {Df ] ) xy = 1 if a* ^ y< and (.D^)^ = 
otherwise. For i G {1, . . . , n}, we have L>- = D^' (g) J®' -1 , where J denotes the |5| x \S\ matrix 
with every entry equal to 1. Matrices Df for i G {n + 1, . . . ,tn} can be expressed similarly by 
suitable permutation of the tensor factors. Then for i G {1, . . . , n}, 

HrWoD^n = ||(r«0/ '" 1 + /0r( t - 1 ))o( J Dj 1) ® j®'- 1 )!! (13) 

= ||(rWo£)j 1) )®7®*- 1 || (14) 
= ||r«o £>f>[|. (15) 

By symmetry, o J5| [| for general i G {1, . . . , in} only depends on the congruence class of i 
modulo n. It follows that ADV(/W) > iADV(/W). 

Although we do not need the converse to establish a direct sum theorem, it can be proven 
as follows. Using semidefinite programming duality, we can express ADV(/) as a minimization 
problem; in particular [19], 

ADV(/) = min max =, (16) 

where the minimization is over sets of probability distributions p x (i), i-e., Y27=lP x ^) = 1 for all 
x £ S. Let achieve the minimum in (|16|) for / = f^ 1 '. Define a set of probability distributions 
pW by p { x\i) := ip^ i/nJ+ i...:z nU /„j + mod n) for i G {1, ...,in}; this is clearly a probability 
distribution for any x G 5*. To ensure f^'(x) ^ f^\y), we must have f^(xj n+ i...Xj n+n ) ^ 
f (Vjn+l ■ ■ ■ Ujn+n) for some j G {0, . . . ,t — 1}. Without loss of generality, suppose j = 1. The 
maximum over x, y G <S* is achieved by taking x% = y% for all i G {n + 1, . . . , in} so that there is 
no contribution to the denominator from these indices. Thus, we find ADV(/W) < t ADV(/W), 
which completes the proof. □ 

As a consequence of this fact, whenever a function / has an optimal adversary lower bound, it 
obeys a direct sum theorem. This can be compared with the multiplicative adversary method [18J, 
in which a multiplicative adversary lower bound implies a strong direct product theorem. 

Note that the lower bound of Theorem |4] applies to the negative adversary method as well |12j . 
so negative adversary lower bounds also imply direct sum theorems. 
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4 Lower bound 



We now apply the result of the previous section to give a nearly optimal lower bound for certificate 
finding. 

The query complexity of certification is clearly Q(d k ^ 2 ), as knowing a certificate allows one to 
evaluate the formula. (Recall that a minimal certificate for a balanced formula is a subset of inputs 
all taking the same value; hence we can learn this value by evaluating one input.) This immediately 
shows that the algorithm of Section [2] is close to optimal for 1-certificate finding. 

It remains to prove the lower bound for O-certificate finding. First, suppose that k is even. In 
this case, a O-certificate consists of one 0-leaf from each of d k ' 2 bottom subtrees, where each subtree 
has size d. Suppose we are told which of the bottom subtrees we need to consider; this can only 
make the problem easier. Then we must find a 0-leaf in each of these subtrees. Intuitively, the best 
strategy for finding these leaves is to run Grover's algorithm for an input of size d independently on 
each of the d k l 2 subtrees. To make this intuition rigorous, we can apply the direct sum theorem for 
search, which says we need at least Q(ty/d) queries to solve t independent instances of the search 
problem on inputs of size d. While we could prove this using Theorem [H it is also implied by the 
strong direct product theorem for search from [2] (which applies even to the problem of finding t 
marked items with the promise that they exist). Thus, with t = d k ^ 2 , we find a lower bound of 
queries. (A similar argument works for 1-certificate finding with k odd, but we do not 

need it.) 

We can apply a similar approach when k is odd. Suppose we could prove a direct sum theorem 
for 1-certifying two-level NAND formulas — in other words, that finding 1-certificates to t independent 
two-level formulas requires t times the number of queries required to certify one such formula. A 
O-certificate with k odd consists of all d 1-leaves of each of d( fe_1 )/ 2 bottom subtrees. If we are told 
which subtrees we must consider one level above, then we must evaluate c?( fc_1 )/ 2 two-level trees. 
Thus, a direct sum theorem would say that we need n^f*" 1 )/ 2 • d) = Q(d ( - k+1 ^ 2 ) queries. 

To prove this direct sum theorem, by Theorem EJ it suffices to give an adversary lower bound 
for the problem of 1-certifying a two-level nand formula. Since we are promised that the formula 
evaluates to 1, at least one of its d subtrees evaluates to 0, i.e., all d inputs to that subtree are 1. 
We further promise that precisely one subtree evaluates to 0, and that in all other subtrees, d — 1 
of the d inputs evaluate to 1, with the remaining input evaluating to 0. These promises only make 
the problem easier. Let S C {0, l} d2 denote the set of such inputs, and let / : S — > {1, . . . , d} be 
defined by fix) = i, where i is the unique index of the subtree that evaluates to 0. 

We claim that ADV(/) = tt(d). To see this, let T be the |5| x \S\ matrix in which T xy = 
unless x and y differ in exactly two bits and fix) ^ f(y), in which case T xy = 1. In the latter case, 

• the subtree which evaluates to in a; evaluates to 1 in y, meaning that one of its d inputs 
switches from 1 in x to in y, and 

• exactly one of d — 1 subtrees which evaluates to 1 in x evaluates to in y, meaning that its 
unique 0-input in x switches to 1 in y. 

Thus, for any fixed x, there are d(d — 1) possible y with fix) ^ f(y)- In other words, T is the 
adjacency matrix of a d(d — l)-regular graph, which means that ||r|| = d(d — 1). 

Now, fixing x as well as an index i, the maximum number of ys with X{ ^ yi is d: if i is an input 
to the subtree evaluating to in x, then we only have the freedom to choose one of d — 1 other 
subtrees in which we switch a fixed input, whereas if i is an input to a subtree evaluating to 1 in 
x, then we only have the freedom to choose one of d inputs to the 0-subtree to switch. This means 
that Di o r is the adjacency matrix of a graph of maximum degree d, which implies \\Di o T\\ < d. 
Overall, we have ADV(/) > d- 1 = 0(d). 
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Note that, more generally, a similar argument can be used to establish a direct sum theorem for 
the problem of certifying fc-level NAND formulas. In particular, the bounded-error quantum query 
complexity of certifying t independent d-regular, £;-level balanced nand formulas, each of which 
evaluates to b G {0, 1}, is ft(^ (fc+1)/2 ) for b = and VL{td k / 2 ) for b = 1. 

5 Open questions 

We have described a nearly optimal quantum algorithm for certifying the value of a formula. This 
leaves several open questions: 

• For constant-degree formulas, there is a logarithmic gap between our lower and upper bounds. 
Is it possible to improve the lower bound or the algorithm (or both)? 

• Since a certificate can be used to verify the value of a formula with zero error in only 0(y/n) 
queries, our result shows in particular that the zero-error quantum query complexity of eval- 
uating a (i-regular, /c-level balanced NAND formula is 0{k 2 d^ k+l ^ 2 ). However, the best known 
lower bound is S7(d fc / 2 ) , from the bounded-error case. Is there a faster quantum algorithm for 
evaluating a formula with zero error that does not work by producing a certificate? (More 
generally, the relationship between bounded- and zero-error quantum query complexity is 
poorly understood.) 

• We have restricted our attention to regular, balanced formulas. What is the quantum query 
complexity of certifying an arbitrary nand formula? Of course, we can apply a similar 
recursive strategy to unbalanced formulas, but in general, it is not clear how Procedure A\ 
should select a 0-subtree, since some subtrees may require more queries to certify than others. 
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